QuestionQ606

Information Security Governance

Internal audit has identified several information-security issues that do not comply with regulatory requirements. What should the information security manager do FIRST?

  • A Create a security exception
  • B Assess the risk to business operations
  • C Perform a vulnerability assessment
  • D Perform a gap analysis to determine needed resources
Explanation

The information security manager should assess the risk to business operations so that regulatory compliance issues can be prioritized according to their potential business impact and risk exposure. Remediation planning, resource-gap analysis, or any consideration of an exception should follow that assessment.

Community Discussion

No comments yet. Be the first to start the discussion!